2026 CVE Vulnerabilities
69,303 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-31871 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31870 | HIGH | 7.5 | 0.5% | Mar 11, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.37.1, when a cpp-httplib cl... |
| CVE-2026-31868 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31867 | MEDIUM | 4.8 | 0.3% | Mar 11, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (I... |
| CVE-2026-31866 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | flagd is a feature flag daemon with a Unix philosophy. Prior to 0.14.2, flagd exposes OFREP (/ofrep/v1/evaluate/...) and... |
| CVE-2026-31863 | MEDIUM | 4.4 | 0.1% | Mar 11, 2026 | Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API ca... |
| CVE-2026-31862 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31861 | HIGH | 8.8 | 6.0% | Mar 11, 2026 | Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1... |
| CVE-2026-31859 | MEDIUM | 6.1 | 0.2% | Mar 11, 2026 | Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in... |
| CVE-2026-31858 | HIGH | 8.8 | 0.4% | Mar 11, 2026 | Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() ... |
| CVE-2026-31857 | HIGH | 8.8 | 0.7% | Mar 11, 2026 | Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in t... |
| CVE-2026-31856 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. A SQL injection ... |
| CVE-2026-30226 | HIGH | 7.5 | 0.4% | Mar 11, 2026 | Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the ... |
| CVE-2026-0231 | MEDIUM | 5.7 | 0.2% | Mar 11, 2026 | An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obta... |
| CVE-2026-0230 | MEDIUM | 4 | 0.1% | Mar 11, 2026 | A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator t... |
| CVE-2026-3429 | MEDIUM | 4.2 | 0.3% | Mar 11, 2026 | A flaw was identified in the Account REST API of Keycloak that allows a user authenticated at a lower security level to ... |
| CVE-2026-31854 | HIGH | 8.8 | 0.3% | Mar 11, 2026 | Cursor is a code editor built for programming with AI. Prior to 2.0 ,if a visited website contains maliciously crafted i... |
| CVE-2026-31853 | MEDIUM | 5.5 | 0.1% | Mar 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9... |
| CVE-2026-31852 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulner... |
| CVE-2026-31840 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-a... |
| CVE-2026-31839 | HIGH | 7.5 | 0.1% | Mar 11, 2026 | Striae is a firearms examiner's comparison companion. A high-severity integrity bypass vulnerability existed in Striae's... |
| CVE-2026-31813 | MEDIUM | 4.8 | 0.1% | Mar 11, 2026 | Supabase Auth is a JWT based API for managing users and issuing JWT tokens. Prior to 2.185.0, a vulnerability has been i... |
| CVE-2026-30868 | HIGH | 8.1 | 0.1% | Mar 11, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.4, multiple OPNsense MVC API endpoints perform ... |
| CVE-2026-30239 | HIGH | 7.1 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when budgets are deleted, the wor... |
| CVE-2026-30236 | MEDIUM | 4.3 | 0.2% | Mar 11, 2026 | OpenProject is an open-source, web-based project management software. Prior to 17.2.0, when editing a project budget and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now